CVE-2025-41646
moderateAuthentication Bypass via Incorrect Type Conversion in KUNBUS RevPi Status
CVE-2025-41646 is a critical authentication bypass in the KUNBUS RevPi Status software package, caused by an incorrect type conversion (CWE-704). An unauthenticated remote attacker can trigger the flawed conversion over the network, without any privileges or user interaction, and thereby bypass the package's authentication entirely. Successful exploitation grants full control of the affected device, compromising confidentiality, integrity, and availability. Affected parties are operators of KUNBUS Revolution Pi (RevPi) industrial devices running the RevPi Status package, with specific version ranges not provided in the source data. As of now there is no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation, though the 51.5% EPSS score (99th percentile) indicates a high probability of exploitation within the next 30 days.
What to do: Inventory RevPi devices for the RevPi Status package and, until a vendor update is applied, restrict network access to the service from untrusted networks. Apply the patched version as published in the VDE CERT advisory for CVE-2025-41646 (fixed versions are not specified in the source data), and monitor for a public exploit given the elevated EPSS score.
| kunbus RevPi Status | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device
- Vendors
- kunbus
- Products
- revpi status
- Weakness
- CWE-704
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.